MD-102 Manage and maintain devices Practice Question
Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?
⚠ Common exam trap
A common mix-up: candidates confuse Intune's device management capabilities with on-premises Group Policy or Active Directory tasks, leading them to incorrectly select options like creating local users or managing DHCP, which are outside Intune's scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remotely wipe a device
Option B is correct because Microsoft Intune supports remote device actions such as a full wipe (and also selective wipe/retire) for Windows 10 devices enrolled in MDM, allowing an administrator to reset the device to factory settings and remove corporate data. Option D is correct because Intune provides built-in BitLocker disk encryption policies (via the Endpoint Security Disk Encryption profile or configuration profiles) that let you enforce and manage BitLocker on Windows 10 devices, including storing recovery keys in Microsoft Entra ID/Intune. Option A is not correct because Intune does not create local user accounts on Windows 10 devices; local account management is done via Group Policy, PowerShell, or other on-premises tools, not Intune MDM policy. Option C is not correct because DHCP settings are configured on the DHCP server or network infrastructure, not through Intune device management policies. Option E is not correct because adding a device to an Active Directory group is an on-premises AD/Group Policy or Microsoft Entra ID dynamic group operation, not an Intune device management action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create local user accounts on the device
Why it's wrong here
Intune manages device configuration and compliance; it does not create local Windows user accounts, which are provisioned by the OS or Group Policy. It is tempting because Intune does deploy account-related scripts and policies, and would be correct if the requirement were configuring device settings rather than creating accounts.
- ✓
Remotely wipe a device
Why this is correct
Intune's remote device actions include wipe, which performs a factory reset removing corporate and personal data. This is distinct from retire, which removes only company data and management, and from selective wipe on supported platforms.
- ✗
Configure DHCP settings
Why it's wrong here
DHCP settings are configured on the network infrastructure or via device configuration profiles at the OS level, not through Intune's device management actions. It is tempting because Intune does deliver network-related configuration profiles, and would be correct if the task were pushing Wi-Fi or VPN settings to devices.
- ✓
Apply BitLocker encryption policies
Why this is correct
BitLocker drive encryption policies deploy through Intune's endpoint security disk encryption profiles, enforcing encryption on Windows 10 devices without Group Policy or on-premises infrastructure. This satisfies the stem's requirement for device management actions available natively within Intune, covering OS volume, fixed drives and removable media via CSP-backed configuration.
- ✗
Add the device to an Active Directory group
Why it's wrong here
Intune manages devices directly and does not add them to Active Directory groups; that is performed in on-premises AD or via Microsoft Entra ID. It is tempting because Intune does support group targeting for policy assignment, and would be correct if the requirement were scoping a policy to a group.
Visual reference
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.